Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 202

Количество 77 202

ubuntu логотип

CVE-2012-5515

больше 13 лет назад

The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2012-5514

больше 13 лет назад

The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2012-5513

больше 13 лет назад

The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2012-5512

больше 13 лет назад

Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.

CVSS2: 3.2
EPSS: Низкий
ubuntu логотип

CVE-2012-5511

больше 13 лет назад

Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2012-5510

больше 13 лет назад

Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2012-5484

больше 13 лет назад

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

CVSS2: 7.9
EPSS: Низкий
ubuntu логотип

CVE-2012-5483

больше 13 лет назад

tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-5482

почти 14 лет назад

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5481

почти 14 лет назад

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5480

почти 14 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-5479

почти 14 лет назад

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5476

больше 6 лет назад

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5474

больше 6 лет назад

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5473

почти 14 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5472

почти 14 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5471

почти 14 лет назад

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5470

почти 14 лет назад

libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5468

больше 13 лет назад

Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an email containing a base64 string that is decoded to incomplete multibyte characters.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5391

больше 12 лет назад

Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-5515

The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5514

The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5513

The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.

CVSS2: 6.9
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5512

Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.

CVSS2: 3.2
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5511

Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5510

Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

CVSS2: 7.9
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5483

tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5482

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.

CVSS2: 5.5
3%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5481

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

CVSS2: 4
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

CVSS2: 6.4
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5479

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

CVSS2: 6.5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5476

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-5474

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-5473

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

CVSS2: 4
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5472

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVSS2: 4
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5471

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVSS2: 6.5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5470

libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.

CVSS2: 4.3
6%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5468

Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an email containing a base64 string that is decoded to incomplete multibyte characters.

CVSS2: 7.5
6%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5391

Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад

Уязвимостей на страницу